Used Windows Certificate Enrollment Control Vulnerability Patch (Windows Me) for Windows?


Editors’ Review

Download.com staff
This update corrects a security flaw in Windows' Certificate Enrollment Control, preventing malicious websites or emails from deleting vital digital certificates.
  • Pros

    • Fixes vulnerability in Certificate Enrollment Control
    • Addresses SmartCard Enrollment control flaw
    • Protects digital certificates from deletion
    • Restores functionality to affected systems
  • Cons

    • Requires minor Web application revisions for some users
    • Details for revisions in Knowledge Base article

Used Windows Certificate Enrollment Control Vulnerability Patch (Windows Me) for Windows?


Explore More


Full Specifications

GENERAL
Release
Latest update
Version
5.131.3659.0
OPERATING SYSTEMS
Platform
Windows
Operating System
  • Windows 10
  • Windows ME
Additional Requirements
Windows Me
POPULARITY
Total Downloads
5,459
Downloads Last Week
0

Report Software

Program available in other languages


Last Updated


User Reviews

3/5

2 User Votes


Developer’s Description

Fix a Windows flaw to stop a Web site or HTML e-mail from deleting digital certificates on your computer.
All versions of Windows ship with an ActiveX control known as the Certificate Enrollment Control, the purpose of which is to allow Web-based certificate enrollments. The control contains a flaw that could enable a Web page, through an extremely complex process, to invoke the control in a way that would delete certificates on a user?s system. An attacker who successfully exploited the vulnerability could corrupt trusted root certificates, EFS encryption certificates, e-mail signing certificates, and any other certificates on the system, thereby preventing the user from using these features.

A new version of the control is available that corrects the vulnerability and can be installed via the patch. As discussed in the Caveats section, customers who operate Web sites that use the Certificate Enrollment Control will need to make minor revisions to their Web applications in order to use the new control. Microsoft Knowledge Base article Q323172 details how to do this. In addition, the patch addresses a similar, but less serious vulnerability discovered in the SmartCard Enrollment control. This control ships with Windows 2000 and Windows XP. A new version of this control is also provided.


Download.com
Your review for Windows Certificate Enrollment Control Vulnerability Patch (Windows Me)